dokploy-deploy

Fail

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PRIVILEGE_ESCALATION]: The manual installation instructions in 'references/getting-started/manual-installation.mdx' include a bash script that performs 'chmod 777 /etc/dokploy'. This grants universal read, write, and execute permissions to a sensitive configuration directory, which is a significant security anti-pattern. The setup process also requires root-level access to the host server.\n- [REMOTE_CODE_EXECUTION]: The documentation encourages installing the software and its dependencies using the 'curl | bash' pattern from remote URLs such as 'dokploy.com/install.sh' and 'get.docker.com'. While these are vendor-provided, this execution method bypasses user verification of the script content.\n- [COMMAND_EXECUTION]: The 'Advanced' settings for applications documented in 'references/applications/advanced.mdx' include a 'Run Command' feature that enables the execution of arbitrary shell commands directly inside containers for debugging and administration.\n- [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface via 'Preview Deployments' in 'references/applications/preview-deployments.mdx'.\n
  • Ingestion points: External data enters the system through GitHub Pull Request branch names and labels.\n
  • Boundary markers: No specific delimiters or safety instructions are mentioned for processing these inputs beyond a general warning against use on public repositories.\n
  • Capability inventory: The skill can execute complex deployment workflows, Docker builds, and management tasks via the Dokploy CLI (references/cli-commands.md).\n
  • Sanitization: The documentation does not specify any sanitization or validation of the PR-provided metadata before it influences the deployment process.\n- [CREDENTIALS_UNSAFE]: Several database connection guide files in 'references/databases/connection/' contain hardcoded placeholder credentials in example connection strings, such as 'mysql://user:password@1.2.4.5:3306/database'.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 3, 2026, 01:24 PM